Sceawere
Vulnerability Detail
CVE-2026-79679UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Weak Credential Vulnerability in mapp Audit
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.7
- Creation Date
- 4h ago
- Vendor
- B&R Industrial Automation GmbH
- Product
- mapp Services
- Attack Type
- CWE-1391 Use of Weak Credentials
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.7",
"pubDate": "2026-09-03T13:06:10.430Z",
"pubdate": "2026-09-03T13:06:10.430Z",
"executiveSummary": "This vulnerability involves the Use of Weak Credentials within the B&R Industrial Automation GmbH mapp Audit component, integrated into mapp Services.\nThe identified flaw allows unauthorized entities to potentially bypass authentication mechanisms or gain elevated access to the auditing functions of the affected systems.\nThe vulnerability affects all versions of mapp Audit used in mapp Services prior to 6.8.0.\nThe risk implication is significant for industrial environments, as unauthorized access to audit logs and system configuration audit trails can lead to the manipulation or concealment of malicious activities.\nThe attacker requires network access to the target service to exploit this vulnerability. No sophisticated authentication tokens are required if the system relies solely on the default or weak credential implementations.\nSuccessful exploitation compromises the integrity and confidentiality of the industrial automation auditing process, potentially allowing an attacker to operate without detection by modifying audit trails.",
"technicalDetails": "The root cause of the vulnerability lies in the implementation of insufficient complexity or hardcoded password policies within the authentication modules of mapp Audit. By utilizing weak, easily guessable, or default credentials for service access, the component fails to enforce adequate identity verification, rendering it susceptible to unauthorized access.\nThe vulnerable component is identified as the authentication logic within mapp Audit, a core service responsible for logging and tracking operational events in B&R Industrial Automation systems.\nThe exploitation flow begins with the attacker identifying the network-reachable mapp Services instance. Upon connection, the attacker leverages the known weak credential weakness to authenticate against the system. Because the credentials lack sufficient entropy or follow predictable patterns, automated brute-force or dictionary attacks can be performed with minimal effort to bypass access controls.\nOnce authenticated, the attacker gains the privileges associated with the account, which in many cases includes read/write access to audit logs or the ability to configure auditing parameters. The post-exploitation behavior involves the manipulation of sensitive log data, potentially deleting records of unauthorized system changes or inserting false entries to obfuscate subsequent malicious actions within the industrial controller environment.\nThis issue is present in all iterations of the software prior to version 6.8.0. The vulnerability is exploitable via the network protocols utilized by mapp Services to interface with external clients or HMI (Human-Machine Interface) systems. There are no secondary authentication requirements once the primary weak credential barrier is breached, allowing for direct interaction with the underlying auditing framework.\nThe technical impact includes a total loss of trust in the integrity of the audit logs, which is a critical failure in industrial safety and compliance environments. By compromising the auditing layer, the attacker can effectively 'blind' security monitoring systems, ensuring their presence remains undetected during the lifecycle of an incident."
}